There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauth
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache A
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptio
Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\System
Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be exe
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. T
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName paramet
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authenticati
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticat
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /ph
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be i
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a
Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php
In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application t
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /ph
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS co
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used
OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in sca
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a
The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL stateme
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be pas
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_en
SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reade
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An u
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started